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Abstract. A working free-space quantum key distribu- 
tion (QKD) system has been developed and tested over 
an outdoor optical path of ~ 1 km at Los Alamos Na- 
tional Laboratory under nighttime conditions. Results 
show that QKD can provide secure real-time key distri- 
bution between parties who have a need to communicate 
secretly. Finally, we examine the feasibility of surface to 
satellite QKD. 

Quantum cryptography was introduced in the mid- 
1980s jU as a new method for generating the shared, se- 
cret random number sequences, known as cryptographic 
keys, that are used in crypto- systems to provide commu- 
nications security. The appeal of quantum cryptography 
is that its security is based on laws of nature, in contrast 
to existing methods of key distribution that derive their 
security from the perceived intractability of certain prob- 
lems in number theory, or from the physical security of 
the distribution process. 

Since the introduction of quantum cryptography, sev- 
eral groups have demonstrated quantum communications 
|^|,D and quantum key distribution over multi- 

kilometer distances of optical fiber. Free-space QKD 
(over an optical path of ~ 30 cm) was first introduced 
in 1991 |Q, and recent advances have led to demonstra- 
tions of QKD over free-space indoor optical paths of 205 
m pi , and outdoor optical paths of 75 m jllj. These 
demonstrations increase the utility of QKD by extending 
it to line-of-site laser communications systems. Indeed 
there are certain key distribution problems in this cate- 
gory for which free-space QKD would have definite prac- 
tical advantages (for example, it is impractical to send 
a courier to a satellite). We are developing such QKD, 
and here we report our results of free-space QKD over 
outdoor optical paths of up to 950 m under nighttime 
conditions. 

The success of QKD over free-space optical paths 
depends on the transmission and detection of single- 
photons against a high background through a turbulent 
medium. Although this problem is difficult, a combi- 
nation of sub-nanosecond timing, narrow filters Jl3| , p^ |, 
spatial filtering |t0| and adaptive optics |l5|] can ren- 
der the transmission and detection problems tractable. 
Furthermore, the essentially non-birefringent nature of 
the atmosphere at optical wavelengths allows the faith- 
ful transmission of the single-photon polarization states 
used in the free-space QKD protocol. 

A QKD procedure starts with the sender, "Alice," gen- 
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erating a secret random binary number sequence. For 
each bit in the sequence, Alice prepares and transmits 
a single photon to the recipient, "Bob," who measures 
each arriving photon and attempts to identify the bit 
value Alice has transmitted. Alice's photon state prepa- 
rations and Bob's measurements are chosen from sets 
of non-orthogonal possibilities. For example, using the 
B92 protocol fif] Alice agrees with Bob (through public 
discussion) that she will transmit a horizontal-polarized 
photon, \h), for each "0" in her sequence, and a right- 
circular-polarized photon, |r), for each "1" in her se- 
quence. Bob agrees with Alice to randomly test the 
polarization of each arriving photon with vertical polar- 
ization, \v), to reveal "Is," or left-circular polarization, 
\£), to reveal "0s." In this scheme Bob will never detect 
a photon for which he and Alice have used a prepara- 
tion/measurement pair that corresponds to different bit 
values, such as \h) and \v), which happens for 50% of the 
bits in Alice's sequence. However, for the other 50% of 
Alice's bits the preparation and measurement protocols 
use non-orthogonal bases, such as for \h) and \£), result- 
ing in a 50% detection probability for Bob, as shown in 
Table |[ Thus, by detecting single-photons Bob identifies 
a random 25% portion of the bits in Alice's random bit 
sequence, assuming a single-photon Fock state with no 
bit loss in transmission or detection. This 25% efficiency 
factor, rjQ, is the price that Alice and Bob must pay for 
secrecy. 

Bob and Alice reconcile their common bits through a 
public discussion by revealing the locations, but not the 
bit values, in the sequence where Bob detected photons; 
Alice retains only those detected bits from her initial se- 
quence. The resulting detected bit sequences comprise 
the raw key material from which a pure key is distilled 
using classical error detection techniques. The single- 
photon nature of the transmissions ensures that an eaves- 
dropper, "Eve," can neither "tap" the key transmissions 
with a beam splitter (BS), owing to the indivisibility of a 
photon [p7f, nor copy them, owing to the quantum "no- 
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FIG. 1. Free-Space QKD Transmitter (Alice) 



cloning" theorem frl8| ]. Furthermore, the non-orthogonal 
nature of the quantum states ensures that if Eve makes 
her own measurements she will be detected through the 
elevated error rate she causes by the irreversible "collapse 
of the wavefunction" . 

The QKD transmitter in our experiment (FIG. 1) 
consisted of a temperature-controlled single-mode (SM) 
fiber-pigtailed diode laser, a fiber to free-space launch 
system, a 2.5-nm bandwidth interference filter (IF), a 
variable optical attenuator, a polarizing beam splitter 
(PBS), a low- voltage Pockels cell, and a 27x beam ex- 
pander. The diode laser wavelength is temperature ad- 
justed to 772 nm, and the laser is configured to emit 
a short pulse of approximately 1-ns length, containing 
~ 10 5 photons. 

A computer control system (Alice) starts the QKD 
protocol by pulsing the diode laser at a rate previously 
agreed upon between herself and the receiving computer 
control system (Bob). Each laser pulse is launched into 
free-space through the IF, and the ~ 1 ns optical pulse 
is then attenuated to an average of less than one pho- 
ton per pulse, based on the assumption of a statistical 
Poisson distribution. (The attenuated pulse only approx- 
imates a "single-photon" state; we tested out the system 
with averages down to < 0.1 photons per pulse. This 
corresponds to a 2-photon probability of < 0.5% and im- 
plies that less than 6 of every 100 detectable pulses will 
contain 2 or more photons.) The photons that are trans- 
mitted by the optical attenuator are then polarized by 
the PBS, which transmits an average of less than one 
\h) photon to the Pockels cell. The Pockels cell is ran- 
domly switched to either pass the light unchanged as \h) 
(zero- wave retardation) or change it to |r) (quarter- wave 
retardation). The random switch setting is determined 
by discriminating the voltage generated by a white noise 
source. 

The QKD receiver (FIG. 2) was comprised of a 8.9 cm 
Cassegrain telescope followed by the receiver optics and 
detectors. The receiver optics consisted of a 50/50 BS 
that randomly directs collected photons onto either of 
two distinct optical paths. The lower optical path con- 
tained a polarization controller (a quarter-wave retarder 
and a half-wave retarder) followed by a PBS to test col- 
lected photons for \h); the upper optical path contained 
a half- wave retarder followed by a PBS to test for |r). 
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FIG. 2. Free-Space QKD Receiver (Bob). 



One output port along each optical path was coupled by 
multi-mode (MM) fiber to a single-photon counting mod- 
ule (SPCM: EG&G part number: SPCM-AQ 142-FL). 
[Although the receiver did not include IFs, the spatial 
filtering provided by the MM fibers effectively reduced 
noise caused by the ambient background during night- 
time operations (~ 1.1 kHz) to negligible levels.] 

A single |r) photon traveling along the lower path en- 
counters the polarization controller, and is converted to 
\v) and reflected away from the SPCM. Conversely, a 
single \h) photon traveling the same path is converted to 
|r) and transmitted toward or reflected away from the 
SPCM in this path with equal probability. Similarly, a 
single \h) photon traveling the upper path is converted 
to \v) and reflected away from the SPCM in this path, 
but a single \r) photon traveling this path is converted 
to \l) and transmitted toward or reflected away from the 
SPCM with equal probability. 

The transmitter and receiver optics were operated over 
240- , 500- , and 950-m outdoor optical paths under night- 
time conditions, with the transmitter and receiver collo- 
cated in order to simplify data acquisition. All optical 
paths were achieved by reflecting the emitted beam from 
a 25.4-cm mirror positioned at the half-way point of the 
transmission distance. 

The optical coupling efficiency between the transmitter 
and receiver for the 950-m path was 77 ~ 14%, which 
accounts for losses between the transmitter and the MM 
fibers at the receiver. Bob's detection probability, 
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is the convolution of the Poisson probability distribution 
of photons in Alice's transmitted weak pulse with average 
photon number n, and the probability that Bob detects 
at least 1 photon. Here, y = (1 — 77s), where r\B = 
V ' Vd • ?7q, and t]d = 65% is Bob's detector efficiency. 
When the transmitter was pulsed at a rate of 20 kHz with 
an average of 0.1 photons per pulse for the 950-m path, 
Eq. [l] gives n ■ r\B = 0.1 • (0.14 ■ 0.25 • 0.65) - 2.3 x 10~ 3 , 
and hence a bit rate in agreement with the experimental 
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TABLE II. A 200-bit sample of Alice's (a) and Bob's (b) 
raw key material generated by free-space QKD over 1 km. 



a 
b 


00000101011101101001000000000001100101010011100010 
00000101011101101001000000000001100101010011100010 


a 
b 


01110111011110111000010010001111100000000101101111 
01110111011110111000010010001111100000000101101111 


a 
b 


10010010100010000011000001011100001111111111000000 

looiooioioooioooooiioooooiomooooimmioioooooo 


a 
b 


10101011011111100111111011110101001101001011101111 
10101011011111100011111011110101001101001011101111 



result of ~ 50 Hz. 

The bit error rate (BER, denned as the ratio of the bits 
received in error to the total number of bits received) 
for the 950-m path was ~ 1.5% when the system was 
operating down to the 0.1 photons per pulse level. (A 
BER of ~ 0.7% was observed over the 240-m optical path 
and a BER of ~ 1.5% was also observed over the 500-m 
optical path.) A sample of raw key material from the 
950-m experiment, with errors, is shown in Table ||. 

Bit errors caused by the ambient background were min- 
imized to less than ~ 1 every 9 s by the narrow gated 
coincidence timing windows (~ 5 ns) and the spatial 
filtering. Further, because detector dark noise (~ 80 
Hz) contributed only about 1 dark count every 125 s, 
we believe that the observed BER was mostly caused by 
misalignment and imperfections in the optical elements 
(wave-plates and Pockels cell). 

This experiment implemented a two-dimensional par- 
ity check scheme that allowed the generation of error-free 
key material. A further stage of "privacy amplification" 
pot is necessary to reduce any partial knowledge gained 
by an eavesdropper to less than 1-bit of information, but 
we have not implemented such a privacy amplification 
protocol at this time. Our free-space QKD system does 
incorporate "one time pad" pl| encryption — also known 
as the Vernam Cipher: the only provably secure encryp- 
tion method — and could also support any other symmet- 
ric key system. 

The original form of the B92 protocol has a weakness 
to an opaque attack by Eve. For example, Eve could mea- 
sure Alice's photons in Bob's basis and only send a dim 
photon pulse when she identifies a bit. However, if Eve 
retransmits each observed bit as a single-photon she will 
noticeably lower Bob's bit-rate. To compensate for the 
additional attenuation to Bob's bit-rate Eve could send 
on a dim photon pulse of an intensity appropriate to raise 
Bob's bit-rate to a level similar to her own bit-rate with 
Alice. [In fact, if Eve sends a bright classical pulse (a 
pulse of a large average photon number) she guarantees 
that Bob's bit-rate is close to her own bit-rate with Alice.] 
However, this type of attack would be revealed by our two 
SPCM system through an increase in "dual-fire" errors, 



which occur when both SPCMs fire simultaneously. In a 
perfect system there would be no dual-fire errors, regard- 
less of the average photon number per pulse, but in an 
imperfect experimental system, where bit-errors occur, 
dual-fire errors will occur. (We use the dual-fire infor- 
mation to estimate the average number of photons per 
pulse reaching the SPCMs.) Our system could also be 
modified to operate under the BB84 protocol p]] which 
also protects against an opaque attack. 

Eve could also passively, or translucently, attack the 
the system using a BS and a receiver identical to Bob's 
(perhaps of even higher efficiency) to identify some of the 
bits for which Alice's weak pulses contains more than 
1 photon, i.e., Eve receives pulses reflected her way by 
the BS which has reflection probability R, whereas Bob 
receives the transmitted pulses, and the BS has trans- 
mission probability T = 1 — R. Introducing a coupling 
and detection efficiency factor t]e, for Eve, analogous to 
Bob's r/B, we find that Eve's photon detection probabil- 
ity is Pe = 1 — e~ nr * E R , whereas Bob's detection prob- 
ability becomes Pb = 1 — e~ nT,nT . (Note: we do not 
explicitly consider any eavesdropping strategy, with or 
without guessing, in which Eve might use more than 2 
detectors. 

The important quantity is the ratio of the number of 
bits Eve shares with Bob to the number of bits Bob and 
Alice share. We find that the probability that Eve and 
Bob will both observe a photon on the same pulse from 
Alice is HQ 

iW - [1 - e- n ^ R ] [1 - e -« T ] . (2) 

To take an extreme case, if Eve's BS has R = 0.9999, her 
efficiency is perfect (i.e., t\e — 0.25), and Alice transmits 
pulses of n — 0.1, then Eve's knowledge Pbae/Pb of Bob 
and Alice's common key will never be more than 2.5%. 
Thus, Alice and Bob have an upper bound on the amount 
of privacy amplification needed to protect against a BS 
attack. Of course, such an attack would cause Bob's 
bit-rate to drop to near zero, and for smaller reflection 
coefficients, R, Eve's information on Bob and Alice's key 
is reduced. For example, if Alice transmits pulses with 
an average of 0.1 photons per pulse, and R = T = 0.5, 
then for every 250 key bits Alice and Bob acquire, Eve 
will know only ~ 3 bits. 

As a final discussion, we consider the feasibility to 
transmit the quantum states required in QKD between 
a ground station and a satellite in a low earth orbit. To 
that end, we designed our QKD system to operate at 772 
nm where the atmospheric transmission from surface to 
space can be as high as 80%, and where single-photon de- 
tectors with efficiencies as high as 65% are commercially 
available. Furthermore, at these optical wavelengths de- 
polarizing effects of atmospheric turbulence are negligi- 
ble, as is the amount of Faraday rotation experienced on 
a surface to satellite path. 
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To detect a single QKD photon it is necessary to know 
when it will arrive. The photon arrival time can be com- 
municated to the receiver by using a bright (classical) 
precursor reference pulse. Received bright pulses allow 
the receiver to set a 1-ns time window within which 
to look for the QKD photon. This short time win- 
dow reduces background photon counts dramatically, and 
the background can be further reduced by using narrow 
bandwidth filters. 

Atmospheric turbulence impacts the rate at which 
QKD photons would be received at a satellite from a 
ground station transmitter. Assuming 30-cm diameter 
optics at both the transmitter and satellite receiver, the 
diffraction- limited spot size would be ~ 1.2-m diameter 
at a 300-km altitude satellite. However, turbulence in- 
duced beam- wander can vary from ~ 2.5- 10 arc-seconds 
leading to a photon collection efficiency at the satellite of 
10 -3 - 1CT 4 . Thus, with a laser pulse rate of 10 MHz, an 
average of one photon-per-pulse, and atmospheric trans- 
mission of ~ 80%, photons would arrive at the collection 
optic at a rate of 800-10,000 Hz. Then, with a 65% 
detector efficiency, the 25% intrinsic efficiency of the B92 
protocol, IFs with transmission efficiencies of ~ 70%, and 
a MM fiber collection efficiency of ~ 40%, we find a key 
generation rate of 35-450 Hz is feasible. With an adap- 
tive beam tilt corrector the key rate could be increased 
by about a factor of 100 leading to a key rate of 3.5-45 
kHz; these rates would double by implementing the BB84 
protocol. 

Errors would arise from background photons collected 
at the satellite. The nighttime earth radiance observed 
at 300 km altitude at the transmission wavelength is ~ 1 
mW raT 2 str -1 /zm -1 , or ~ 4 x 10 16 photons s _1 m~ 2 
str -1 /im" 1 , during a full moon, and drops to ~ 10 
photons s _1 m str -1 /zm during a new moon. As- 
suming a 5 arc-seconds receiver field of view, and 1-nm 
IFs preceding the detectors, a background rate of ~ 800 
Hz (full moon), and ~ 20 Hz (new moon) would be ob- 
served (with a detector dark count rate of ~ 50 Hz, the 
error rate will be dominated by background photons dur- 
ing full moon periods, and by detector noise during a new 
moon). We infer a BER from background photons of 
- 9 x 10~ 5 -10~ 3 (full moon), and - 2 x 10~ 6 -3 x 10" 5 
(new moon). 

During daytime orbits the background radiance would 
be much larger (~ 10 22 photons s _1 m~ 2 str" 1 /zm" 1 ), 
leading to a BER of ~ 2 x 10 -2 - 3 x 10 _1 , if an atomic va- 
por filter (24] of ~ 10 ~ 3 nm bandwidth was used instead 
of the IF. [Note: it would also be possible to place the 
transmitter on the satellite. In this situation, the beam 
wander is similar (2.5-10 arc-seconds), but it is only over 
the lowest ~ 2 km of the atmosphere. In this situation, 
the bit-rate would improve by ~ 150, decreasing the BER 
by the same amount.] 

Because the optical influence of turbulence is domi- 
nated by the lowest ~ 2 km of the atmosphere, our exper- 



imental results and this simple analysis show that QKD 
between a ground station and a low-earth orbit satellite 
should be possible on nighttime orbits and possibly even 
in full daylight. During the several minutes that a satel- 
lite would be in view of the ground station there would be 
adequate time to generate tens of thousands of raw key 
bits, from which a shorter error- free key stream of several 
thousand bits would be produced after error correction 
and privacy amplification. 

This Letter demonstrates practical free-space QKD 
through a turbulent medium under nighttime conditions. 
We have described a system that provides two parties a 
secure method to secretly communicate with a simple 
system based on the B92 protocol. We presented two at- 
tacks on this protocol and demonstrated the protocol's 
built in protections against them. This system was op- 
erated at a variety of average photon number per pulse 
down to an average of < 0.1 photons per pulse. The 
results were achieved with low BERs, and the 240-m ex- 
periment demonstrated that BERs of 0.7% or less are 
achievable with this system. From these results we be- 
lieve that it will be feasible to use free-space QKD for 
re-keying satellites in low-earth orbit from a ground sta- 
tion. 

Correspondence and requests for materials to William 
T. Buttler. Email: buttler@lanl.gov 
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